Latest CVE Feed
-
9.8
CRITICALCVE-2025-3828
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injectio... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3726
A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component CD Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. T... Read more
- Published: Apr. 16, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3605
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating t... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3710
The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3684
A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. This issue affects some unknown processing of the file stu_list.php of the component Child Management. The manipulation of the argument s... Read more
Affected Products : kindergarten_management_system- Published: Apr. 16, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3681
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MODE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3481
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required... Read more
Affected Products : pacs_server- Published: May. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3484
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required... Read more
Affected Products : pacs_server- Published: May. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-2107
A vulnerability, which was classified as critical, was found in IBOS 4.5.5. Affected is an unknown function of the file file/personal/del&op=recycle. The manipulation of the argument fids leads to sql injection. It is possible to launch the attack remotel... Read more
Affected Products : ibos- EPSS Score: %0.06
- Published: Apr. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3515
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attac... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- Published: Jun. 17, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3466
langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the ability to override global functions in JavaScript, such as pa... Read more
- Published: Jul. 07, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-3693
A vulnerability was found in Tenda W12 3.0.0.5. It has been rated as critical. Affected by this issue is the function cgiWifiRadioSet of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The e... Read more
- Published: Apr. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3589
A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affected is an unknown function of the file /manage_class.php. The manipulation of the argument ID leads to sql injection. It is possible to ... Read more
Affected Products : music_class_enrollment_system- Published: Apr. 14, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3483
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required... Read more
Affected Products : pacs_server- Published: May. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3482
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MedDream PACS Server. Authentication is not required... Read more
Affected Products : pacs_server- Published: May. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3374
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-2151
A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It ... Read more
- EPSS Score: %0.05
- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3350
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/view-enquiry.php. The manipulation of the argument viewid leads to sql injection. It is possi... Read more
Affected Products : old_age_home_management_system- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3313
A vulnerability, which was classified as critical, was found in PHPGurukul Men Salon Management System 1.0. Affected is an unknown function of the file /admin/add-customer.php. The manipulation of the argument Name leads to sql injection. It is possible t... Read more
Affected Products : men_salon_management_system- Published: Apr. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3331
A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. This issue affects some unknown processing of the file /payment_save.php. The manipulation of the argument mode leads to sql injecti... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection